CWE · MITRE source
CWE-345Insufficient Verification of Data Authenticity
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Last updated: 22 August 2026 20:22 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: mostly · 26 mapping(s) from 7 framework(s): CAPEC 12 (partial) · ATT&CK 6 (partial) · STIG oracle linux 8 2 (mostly) · STIG rhel 7 2 (mostly) · STIG rhel 8 2 (mostly) · STIG oracle linux 9 1 (mostly) · STIG rhel 9 1 (mostly)
OWASP Top 10 for Web (2025)
This weakness contributes to A08:2025 Software or Data Integrity Failures.
Control responseHuman-reviewed
Answering this weakness across the control lifecycle, from our framework cross-walks.
RC.RP-05
- 8 hardening rules · 5 OS baselines
V3.5.5
NIST 800-53 r5 controls that address this weakness (9)AI-assisted
Showing the 7 most specific. Generic controls that address many weakness types are collapsed below.
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
SC-17 | Public Key Infrastructure Certificates | SC | Use of approved PKI certificates provides verifiable data authenticity and origin for communications and artifacts. |
SC-20 | Secure Name/Address Resolution Service (Authoritative Source) | SC | Mandates provision of authenticity and integrity artifacts that enable verification of name/address resolution data. |
SC-21 | Secure Name/Address Resolution Service (Recursive or Caching Resolver) | SC | Requires explicit verification of data authenticity from authoritative sources, preventing acceptance of unauthenticated resolution responses. |
SR-4 | Provenance | SR | Provenance documentation and monitoring directly enables verification of authenticity for components and data throughout their history. |
SR-9 | Tamper Resistance and Detection | SR | The control implements verification mechanisms that detect tampering by ensuring data authenticity. |
PT-8 | Computer Matching Requirements | PT | Directly requires independent verification of matching output before adverse decisions, mitigating insufficient authenticity checks on data from external sources. |
SI-7 | Software, Firmware, and Information Integrity | SI | Mandates verification of data authenticity for software, firmware, and information. |
Show 2 more broadly-applicable controls
SC-33 | Transmission Preparation Integrity | SC | Control requires verification of data authenticity/integrity (e.g., checksums) after aggregation/packing, directly reducing exploitation of insufficient verification before transmission. |
SC-45 | System Time Synchronization | SC | Time synchronization supports reliable freshness verification when checking data authenticity across systems or components. |
MITRE ATT&CK techniques this weakness enables
Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing).
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial). gov = governs / implements (a mandate, not coverage).
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2022-26871 KEV UPD | 9.9 | 9.8 | 0.1963 | 2022-03-29 |
CVE-2016-4553 UPD | 8.8 | 8.6 | 0.7997 | 2016-05-10 |
CVE-2023-38831 KEV UPD | 8.5 | 7.8 | 0.9781 | 2023-08-23 |
CVE-2016-4554 UPD | 8.0 | 8.6 | 0.3889 | 2016-05-10 |
CVE-2018-19971 UPD | 7.8 | 9.8 | 0.0303 | 2019-04-16 |
CVE-2019-11235 UPD | 7.8 | 9.8 | 0.0357 | 2019-04-22 |
CVE-2022-31813 UPD | 7.8 | 9.8 | 0.0335 | 2022-06-09 |
CVE-2025-59934 UPD | 7.8 | 9.4 | 0.0804 | 2025-09-26 |
CVE-2013-2167 UPD | 7.7 | 9.8 | 0.0197 | 2019-12-10 |
CVE-2020-28900 UPD | 7.7 | 9.8 | 0.0236 | 2021-05-24 |
CVE-2021-37421 UPD | 7.7 | 9.8 | 0.0249 | 2021-08-30 |
CVE-2017-3198 UPD | 7.6 | 9.8 | 0.0160 | 2018-07-09 |
CVE-2022-25262 UPD | 7.6 | 9.8 | 0.0144 | 2022-02-25 |
CVE-2022-31800 UPD | 7.6 | 9.8 | 0.0153 | 2022-06-21 |
CVE-2024-45410 | 7.6 | 9.8 | 0.0150 | 2024-09-19 |
CVE-2015-3956 UPD | 7.5 | 9.8 | 0.0095 | 2019-03-25 |
CVE-2019-18835 UPD | 7.5 | 9.8 | 0.0086 | 2019-11-08 |
CVE-2022-0715 UPD | 7.5 | 9.1 | 0.0585 | 2022-03-09 |
CVE-2020-14115 UPD | 7.5 | 9.8 | 0.0112 | 2022-03-10 |
CVE-2022-31801 UPD | 7.5 | 9.8 | 0.0108 | 2022-06-21 |
CVE-2022-30315 UPD | 7.5 | 9.8 | 0.0091 | 2022-07-28 |
CVE-2023-4699 UPD | 7.5 | 10.0 | 0.0075 | 2023-11-06 |
CVE-2025-59951 UPD | 7.5 | 9.1 | 0.0465 | 2025-10-01 |
CVE-2019-6695 UPD | 7.4 | 9.8 | 0.0077 | 2019-08-23 |
CVE-2019-2289 UPD | 7.4 | 9.8 | 0.0061 | 2019-11-21 |